Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Nukeviet

First CVE: Jun 23, 2020Active for: 6 yearsTotal CVEs: 13
29.8
VTI Score
Low

Nukeviet is a content-management and e-government platform with a modestly sized but strategically positioned presence in the vulnerability landscape, particularly in Southeast Asian public administration deployments. Its vulnerabilities skew strongly toward critical-severity outcomes and concentrate in the core Nukeviet and e-Government products through recurrent application-layer weakness classes including cross-site request forgery, SQL injection, deserialization flaws, cross-site scripting, and code injection—a profile typical of PHP-based CMS platforms with complex input-handling and template-processing surfaces. Defenders managing public-sector or government-facing instances should prioritize security assessment and patch deployment for this vendor; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
13
Total CVEs
More Total CVEs than 94% of tracked vendors
1.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 75% of tracked vendors
7.5
Avg CVSS Score
Higher Avg CVSS Score than 57% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Nukeviet over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 23, 2020
6 years ago
Most Recent CVE
Aug 9, 2025
349 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-21809CRITICAL
SQL Injection vulnerability in NukeViet CMS module Shops 4.0.29 and 4.3 via the (1) listid parameter in detail.php and the (2) group_price or groupid parameters in search_result.ph
Jul 30, 20219.830NONO
CVE-2020-21808CRITICAL
SQL Injection vulnerability in NukeViet CMS 4.0.10 - 4.3.07 via:the topicsid parameter in modules/news/admin/addtotopics.php.
Jul 30, 20219.829NONO
CVE-2020-13155HIGH
clearsystem.php in NukeViet 4.4 allows CSRF with resultant HTML injection via the deltype parameter to the admin/index.php?nv=webtools&op=clearsystem URI.
Jun 23, 20208.828NONO
CVE-2024-36528HIGH
nukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before have a Deserialization vulnerability which results in code execution via /admin/extensions/download.php and /admin/e
Jun 10, 20248.826NONO
CVE-2019-7725CRITICAL
includes/core/is_user.php in NukeViet before 4.3.04 deserializes the untrusted nvloginhash cookie (i.e., the code relies on PHP's serialization format when JSON can be used to elim
Dec 31, 20209.825NONO
CVE-2019-7726CRITICAL
modules/banners/funcs/click.php in NukeViet before 4.3.04 has a SQL INSERT statement with raw header data from an HTTP request (e.g., Referer and User-Agent).
Dec 31, 20209.824NONO
CVE-2020-13156MEDIUM
modules\users\admin\add_user.php in NukeViet 4.4 allows CSRF to add a user account via the admin/index.php?nv=users&op=user_add URI.
Jun 23, 20206.522NONO
CVE-2020-22765MEDIUM
Cross Site Scripting (XSS) vulnerability in NukeViet cms 4.4.0 via the editor in the News module.
Jul 30, 20216.121NONO
CVE-2025-8772MEDIUM
A vulnerability, which was classified as problematic, has been found in Vinades NukeViet up to 4.5.06. This issue affects some unknown processing of the file /admin/index.php?langu
Aug 9, 20254.318NONO
CVE-2024-36531MEDIUM
nukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before are vulnerable to arbitrary code execution via the /admin/extensions/upload.php component.
Jun 10, 20245.718NONO
View all 13 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products13 CVEs
54%
15%
31%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network13 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (46.2%)
Unknown0 (0.0%)
Required7 (53.8%)
Privileges Required
Low3 (23.1%)
High1 (7.7%)
None9 (69.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Nukeviet.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Nukeviet — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Nukeviet's Products

View all 2 CNAs →

Top CWEs